What is CVE-2026-19007?
CVE-2026-19007 is an improper privilege management vulnerability in the `isApprovedElevatedSender` function of the `src/auto-reply/reply/reply-elevated.ts` file in mf-yang openclaw-cn up to version 0.2.1. This flaw allows remote exploitation, and users are advised to update to the latest patched version.
Azərbaycanca: CVE-2026-19007 mf-yang openclaw-cn proqramının 0.2.1 versiyasına qədər olan versiyalarında `src/auto-reply/reply/reply-elevated.ts` faylında `isApprovedElevatedSender` funksiyasında düzgün olmayan imtiyaz idarəetməsi zəifliyidir. Bu zəiflik uzaqdan hücum etməyə imkan verir, istifadəçilərə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which file in mf-yang openclaw-cn contains the CVE-2026-19007 vulnerability?
The vulnerability is located in the `isApprovedElevatedSender` function of the `src/auto-reply/reply/reply-elevated.ts` file.
What should users of mf-yang openclaw-cn do to mitigate CVE-2026-19007?
Users are advised to update to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.